Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Store' = '<Current directory>\SecHealthUII.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Skype Web' = '%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\SecHealthUII.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\sechealthuii.exe
- <Current directory>\sechealthuii.exe
- %TEMP%\_mei10202\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei10202\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\_mei10202\base_library.zip
- %TEMP%\_mei10202\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei10202\libcrypto-1_1.dll
- %TEMP%\_mei10202\libffi-7.dll
- %TEMP%\_mei10202\libssl-1_1.dll
- %TEMP%\_mei10202\pyexpat.pyd
- %TEMP%\_mei10202\python310.dll
- %TEMP%\_mei10202\select.pyd
- %TEMP%\_mei10202\ucrtbase.dll
- %TEMP%\_mei10202\unicodedata.pyd
- %TEMP%\_mei10202\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei10202\_ssl.pyd
- <Current directory>\coinbase_checker.exe
- <Current directory>\coinbase.png
- %TEMP%\_mei10202\vcruntime140.dll
- %TEMP%\_mei10202\_asyncio.pyd
- %TEMP%\_mei10202\_bz2.pyd
- %TEMP%\_mei10202\_ctypes.pyd
- %TEMP%\_mei10202\_decimal.pyd
- %TEMP%\_mei10202\_hashlib.pyd
- %TEMP%\_mei10202\_lzma.pyd
- %TEMP%\_mei10202\_multiprocessing.pyd
- %TEMP%\_mei10202\_overlapped.pyd
- %TEMP%\_mei10202\_queue.pyd
- %TEMP%\_mei10202\_socket.pyd
- %TEMP%\_mei10202\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\_mei10202\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei10202\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\_mei10202\certifi\cacert.pem
- %TEMP%\_mei10202\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei10202\base_library.zip
- %TEMP%\_mei10202\certifi\cacert.pem
- %TEMP%\_mei10202\libcrypto-1_1.dll
- %TEMP%\_mei10202\libffi-7.dll
- %TEMP%\_mei10202\libssl-1_1.dll
- %TEMP%\_mei10202\pyexpat.pyd
- %TEMP%\_mei10202\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\_mei10202\python310.dll
- %TEMP%\_mei10202\unicodedata.pyd
- %TEMP%\_mei10202\vcruntime140.dll
- %TEMP%\_mei10202\_asyncio.pyd
- %TEMP%\_mei10202\_bz2.pyd
- %TEMP%\_mei10202\_ctypes.pyd
- %TEMP%\_mei10202\_decimal.pyd
- %TEMP%\_mei10202\_hashlib.pyd
- %TEMP%\_mei10202\_lzma.pyd
- %TEMP%\_mei10202\_multiprocessing.pyd
- %TEMP%\_mei10202\_overlapped.pyd
- %TEMP%\_mei10202\_queue.pyd
- %TEMP%\_mei10202\select.pyd
- %TEMP%\_mei10202\ucrtbase.dll
- %TEMP%\_mei10202\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\_mei10202\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei10202\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei10202\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei10202\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei10202\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\_mei10202\_socket.pyd
- %TEMP%\_mei10202\_ssl.pyd
- ClassName: 'EDIT' WindowName: ''
- '<Current directory>\sechealthuii.exe'
- '<Current directory>\coinbase_checker.exe'